FORENSIA

ATT&CK · T1552.004 · sub-technique

Private Keys

Tactics: credential-access

About

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as <code>~/.ssh</code> for SSH keys on * nix-based systems or <code>C:&#92;Users&#92;(username)&#92;.ssh&#92;</code> on Windows. Adversary tools may also search compromised systems for file extensions relating to cryptographic keys and certificates. When a device is registered to Entra ID, a device key and a transport key are generated and used to verify the device’s identity. An adversary with access to the device may be able to export the keys in order to impersonate the device. On network devices, private keys may be exported via Network Device CLI commands such as `crypto pki export`. Some private keys require a password or passphrase for operation, so an adversary may also use Input Capture for keylogging or attempt to Brute Force the passphrase off-line. These private keys can be used to authenticate to Remote Services like SSH or for use in decrypting other collected files such as email.

Platforms: Linux, macOS, Network Devices, WindowsParent: T1552 Unsecured CredentialsMITRE ATT&CK ↗

Used by actors

6 known groups

Software

11 malware/tools implement this

MimikatzjRATEmpireEburyMacheteKinsingHildegardFoggyWebAADInternalsMafaldaTroll Stealer

Corpus indicators tagged with this technique

45 indicators in the corpus carry T1552.004.

IndicatorTypeFamilySevSrc
cve-2016-0638cvephishing851
cve-2021-29441cve851
cve-2025-7852cve851
cve-2025-7443cve851
cve-2025-34085cve851
cve-2025-12057cve851
cve-2026-3844cve851
cve-2026-0740cve851
cve-2026-1969cve851
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75ehashsupply_chain801
6506d31707a39949f89534bf9705bcf889f1ecae3dbc6f4ff88d67a8be3d01b2hashsupply_chain802
6d332f814f15f19758d65026bbfd0a8c49671b319ec77b8fa1b27fc48afff7d9hashsupply_chain802
7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8hashsupply_chain801
877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3echashsupply_chain801
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144hashsupply_chain801
aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5hashsupply_chain801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301hashsupply_chain801
84f7e396a48913851a10cc78c5cc22a25634564abd0694465236d2f365e2bdeesha256801
c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9eahashsupply_chain801
fc4109f5dd1d30b65dd60e57dc639ac1d313bfa5241e36e61fbc4aabc1cda482sha256phishing807
00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4csha256supply_chain801
f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afcsha256supply_chain801
069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44cehashsupply_chain801
22bf76fe317ea6769bd38619bd440e42d119bd6bsha1supply_chain781
0f57a2bb4c0696170b73e2d35f17c5a6f2f910d7sha1781
843d2017c4ded1dbb694dd4bf20bcd9e92af92f6sha1781
9890950adcbc2478e7a080234f053214adbad44esha1supply_chain781
a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2sha1supply_chain781
c70e105e212ff3c1daa04bb2a62507717f296b0bsha1supply_chain782

Showing the top 30 by severity of 45.